Incident response

MonoDuty Webhooks

Create MonoDuty Webhooks, send the production JSON payload, and handle validation, idempotent retries, conflicts, and token rotation.

Webhooks

MonoDuty accepts native JSON over HTTPS at a source-specific URL:

POST https://mndty.com/YOUR_WEBHOOK_TOKEN

The endpoint is intentionally tool-neutral. A sender or adapter must map its native payload to the fields below.

Create and own a source

  1. Create or select the team-owned service.
  2. Create an explicit Webhook source.
  3. Copy the one-time URL into the sender's secret configuration.
  4. Send a controlled test and verify the owning team, incident, and notification route.

Rotate the source token immediately if the URL is exposed.

Payload contract

At least one of title or message is required. Unknown provider-native wrappers are not automatically transformed.

FieldRequirementLimit
titleRequired when message is absent255 characters
messageRequired when title is absent10,000 characters
descriptionOptional string10,000 characters
severityOptional: CRITICAL, HIGH, MEDIUM, LOWEnum
dedup_keyOptional fallback for Idempotency-Key191 characters
sourceOptional source label191 characters
metadataOptional JSON object/arrayBounded depth, count, and string length
{
  "title": "Database replication lag",
  "severity": "HIGH",
  "description": "Replica lag exceeded 30 seconds",
  "source": "prometheus-transformer",
  "metadata": {"cluster":"prod-mysql-01"}
}

Security and retries

The current contract authenticates with the high-entropy token in the URL over HTTPS. It does not advertise HMAC request signing. Keep the URL secret, rotate it after exposure, and do not place it in query strings, analytics, or access logs.

Use a stable Idempotency-Key for retries. Same key plus the canonically identical payload returns HTTP 200, the original incident, and duplicate: true. The same key with a different payload returns HTTP 409 with code idempotency_conflict. Replays never update an incident.